Junglewise Threat Intelligence

CVE-2025-2274: Forcepoint Web Security Stored XSS in Management Console

CVE-2025-2274 · Severity: medium · CVSS 6.1 · Published 2026-03-16

Executive brief

Forcepoint Web Security is an on-premises solution used to monitor and secure corporate web traffic. A vulnerability in this product allows an attacker to inject malicious scripts into the management interface that are then stored and executed when an administrator views certain pages. This could lead to unauthorized actions being performed in the context of the administrator's session, potentially compromising the security configuration of the network.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in Forcepoint Web Security (On-Prem) for Windows through version 8.5.6. The flaw is caused by improper neutralization of user-supplied input during the generation of web pages within the management console (CWE-79). An attacker can exploit this by submitting malicious scripts that are stored on the server and subsequently executed in the browser of a victim (typically an administrator) who views the affected page. While the CVSS 4.0 score provided by the vendor suggests an adjacent network vector, the NVD CVSS 3.1 assessment classifies it as a network-reachable attack requiring user interaction. Successful exploitation can lead to session hijacking or unauthorized configuration changes.

Affected products

  • Forcepoint Web Security (On-Prem) through 8.5.6

Timeline

  • 2026-03-16: disclosed
  • 2026-03-16: advisory

References